implementing-iso-27001-information-security-management

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Implementing ISO 27001 Information Security Management

ISO 27001信息安全管理体系实施

Overview

概述

ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete lifecycle from scoping through certification, including Annex A control selection, risk assessment methodology, Statement of Applicability (SoA) creation, and continuous improvement processes.
ISO/IEC 27001:2022是建立、实施、维护和持续改进信息安全管理体系(ISMS)的国际标准。本技能涵盖从范围规划到认证的完整生命周期,包括附录A控制措施选择、风险评估方法论、适用性声明(SoA)制定以及持续改进流程。

When to Use

适用场景

  • When deploying or configuring implementing iso 27001 information security management capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation
  • 在您的环境中部署或配置ISO 27001信息安全管理能力时
  • 建立符合合规要求的安全控制措施时
  • 构建或改进该领域的安全架构时
  • 开展需要此类实施的安全评估时

Prerequisites

前置条件

  • Understanding of information security principles and risk management concepts
  • Familiarity with organizational governance structures and business processes
  • Knowledge of IT infrastructure, network architecture, and data flows
  • Access to ISO/IEC 27001:2022 and ISO/IEC 27002:2022 standards documents
  • 了解信息安全原则和风险管理概念
  • 熟悉组织治理结构和业务流程
  • 掌握IT基础设施、网络架构和数据流相关知识
  • 可获取ISO/IEC 27001:2022和ISO/IEC 27002:2022标准文档

Core Concepts

核心概念

ISMS Clauses (4-10)

ISMS条款(第4-10条)

The management system requirements define what must be done:
  • Clause 4 - Context of the Organization: Define scope, interested parties, and internal/external issues
  • Clause 5 - Leadership: Top management commitment, information security policy, roles and responsibilities
  • Clause 6 - Planning: Risk assessment process, risk treatment plan, information security objectives
  • Clause 7 - Support: Resources, competence, awareness, communication, documented information
  • Clause 8 - Operation: Operational planning, risk assessment execution, risk treatment implementation
  • Clause 9 - Performance Evaluation: Monitoring, measurement, internal audit, management review
  • Clause 10 - Improvement: Nonconformities, corrective actions, continual improvement
管理体系要求定义了必须完成的事项
  • 第4条 - 组织环境:定义范围、相关方以及内外部问题
  • 第5条 - 领导力:最高管理层承诺、信息安全政策、角色与职责
  • 第6条 - 规划:风险评估流程、风险处置计划、信息安全目标
  • 第7条 - 支持:资源、能力、意识、沟通、文件化信息
  • 第8条 - 运行:运行规划、风险评估执行、风险处置实施
  • 第9条 - 绩效评价:监控、测量、内部审核、管理评审
  • 第10条 - 改进:不符合项、纠正措施、持续改进

Annex A Controls (2022 Edition)

附录A控制措施(2022版)

The 2022 revision restructured 93 controls into four categories:
CategoryControlsExamples
Organizational (A.5)37 controlsPolicies, roles, threat intelligence, cloud security
People (A.6)8 controlsScreening, awareness, remote working, reporting
Physical (A.7)14 controlsPerimeters, entry controls, equipment security
Technological (A.8)34 controlsAccess control, cryptography, logging, secure development
2022版修订将93项控制措施重组为四大类别:
类别控制措施数量示例
组织类(A.5)37项政策、角色、威胁情报、云安全
人员类(A.6)8项筛选、意识培训、远程办公、报告机制
物理类(A.7)14项边界防护、准入控制、设备安全
技术类(A.8)34项访问控制、加密技术、日志记录、安全开发

New Controls in 2022 Edition

2022版新增控制措施

11 new controls were added:
  1. A.5.7 - Threat Intelligence
  2. A.5.23 - Information Security for Cloud Services
  3. A.5.30 - ICT Readiness for Business Continuity
  4. A.7.4 - Physical Security Monitoring
  5. A.8.9 - Configuration Management
  6. A.8.10 - Information Deletion
  7. A.8.11 - Data Masking
  8. A.8.12 - Data Leakage Prevention
  9. A.8.16 - Monitoring Activities
  10. A.8.23 - Web Filtering
  11. A.8.28 - Secure Coding
新增了11项控制措施:
  1. A.5.7 - 威胁情报
  2. A.5.23 - 云服务信息安全
  3. A.5.30 - 业务连续性ICT就绪度
  4. A.7.4 - 物理安全监控
  5. A.8.9 - 配置管理
  6. A.8.10 - 信息删除
  7. A.8.11 - 数据掩码
  8. A.8.12 - 数据泄漏防护
  9. A.8.16 - 监控活动
  10. A.8.23 - 网页过滤
  11. A.8.28 - 安全编码

Workflow

工作流程

Phase 1: Gap Analysis and Scoping (Weeks 1-4)

阶段1:差距分析与范围界定(第1-4周)

  1. Define ISMS scope boundaries (locations, business units, systems)
  2. Identify interested parties and their requirements
  3. Perform gap analysis against ISO 27001:2022 requirements
  4. Document internal and external context (PESTLE, SWOT)
  5. Obtain top management commitment and allocate budget
  1. 定义ISMS范围边界(地点、业务单元、系统)
  2. 识别相关方及其需求
  3. 针对ISO 27001:2022要求开展差距分析
  4. 记录内外部环境(PESTLE、SWOT分析)
  5. 获取最高管理层承诺并分配预算

Phase 2: Risk Assessment (Weeks 5-10)

阶段2:风险评估(第5-10周)

  1. Define risk assessment methodology (asset-based, scenario-based, or hybrid)
  2. Create asset inventory covering information, people, processes, technology
  3. Identify threats and vulnerabilities for each asset
  4. Assess risk likelihood and impact using defined criteria
  5. Calculate risk levels and determine risk treatment options (mitigate, accept, transfer, avoid)
  6. Develop Risk Treatment Plan (RTP)
  1. 定义风险评估方法论(基于资产、基于场景或混合模式)
  2. 创建涵盖信息、人员、流程、技术的资产清单
  3. 识别每项资产对应的威胁与漏洞
  4. 使用既定标准评估风险可能性与影响
  5. 计算风险等级并确定风险处置选项(缓解、接受、转移、规避)
  6. 制定风险处置计划(RTP)

Phase 3: Control Selection and SoA (Weeks 11-14)

阶段3:控制措施选择与SoA制定(第11-14周)

  1. Map risk treatments to Annex A controls
  2. Create Statement of Applicability (SoA) documenting:
    • Which controls are applicable and justification
    • Which controls are excluded and justification
    • Implementation status of each control
  3. Design control implementation plans with owners and timelines
  1. 将风险处置措施映射至附录A控制措施
  2. 制定适用性声明(SoA),记录:
    • 适用的控制措施及理由
    • 排除的控制措施及理由
    • 每项控制措施的实施状态
  3. 设计带有负责人和时间线的控制措施实施计划

Phase 4: Implementation (Weeks 15-30)

阶段4:实施(第15-30周)

  1. Develop and approve information security policy
  2. Implement selected Annex A controls
  3. Create mandatory documented procedures:
    • Information Security Policy (A.5.1)
    • Risk Assessment Process (Clause 6.1.2)
    • Risk Treatment Process (Clause 6.1.3)
    • Internal Audit Programme (Clause 9.2)
    • Management Review Process (Clause 9.3)
    • Corrective Action Procedure (Clause 10.1)
  4. Deploy technical controls and security tooling
  5. Conduct security awareness training for all personnel
  1. 制定并批准信息安全政策
  2. 实施选定的附录A控制措施
  3. 创建强制性文件化流程:
    • 信息安全政策(A.5.1)
    • 风险评估流程(第6.1.2条)
    • 风险处置流程(第6.1.3条)
    • 内部审核方案(第9.2条)
    • 管理评审流程(第9.3条)
    • 纠正措施流程(第10.1条)
  4. 部署技术控制措施与安全工具
  5. 为所有人员开展安全意识培训

Phase 5: Internal Audit and Management Review (Weeks 31-36)

阶段5:内部审核与管理评审(第31-36周)

  1. Plan and execute internal audit programme covering all clauses and applicable controls
  2. Document audit findings and nonconformities
  3. Implement corrective actions with root cause analysis
  4. Conduct management review covering:
    • Status of previous actions
    • Changes in internal/external issues
    • Information security performance metrics
    • Audit results and risk assessment outcomes
    • Opportunities for improvement
  1. 规划并执行覆盖所有条款及适用控制措施的内部审核方案
  2. 记录审核发现与不符合项
  3. 通过根本原因分析实施纠正措施
  4. 开展管理评审,涵盖:
    • 既往措施的状态
    • 内外部问题的变化
    • 信息安全绩效指标
    • 审核结果与风险评估成果
    • 改进机会

Phase 6: Certification Audit (Weeks 37-42)

阶段6:认证审核(第37-42周)

  1. Stage 1 Audit: Documentation review, readiness assessment
  2. Address Stage 1 findings
  3. Stage 2 Audit: On-site assessment of ISMS effectiveness
  4. Resolve any nonconformities (major NCRs require re-audit)
  5. Receive ISO 27001 certification (valid for 3 years)
  1. 第一阶段审核:文档审查、就绪性评估
  2. 解决第一阶段审核发现的问题
  3. 第二阶段审核:现场评估ISMS有效性
  4. 解决所有不符合项(重大不符合项需重新审核)
  5. 获取ISO 27001认证(有效期3年)

Phase 7: Continual Improvement (Ongoing)

阶段7:持续改进(持续进行)

  1. Annual surveillance audits (Years 1 and 2)
  2. Recertification audit (Year 3)
  3. Regular risk reassessment and control effectiveness reviews
  4. Incident-driven improvements and lessons learned integration
  1. 年度监督审核(第1年和第2年)
  2. 重新认证审核(第3年)
  3. 定期重新评估风险并审查控制措施有效性
  4. 基于事件驱动的改进及经验教训整合

Key Artifacts

关键产出物

  • ISMS Scope Document
  • Information Security Policy
  • Risk Assessment Methodology
  • Risk Register and Risk Treatment Plan
  • Statement of Applicability (SoA)
  • Internal Audit Reports
  • Management Review Minutes
  • Corrective Action Register
  • Metrics and KPI Dashboard
  • ISMS范围文档
  • 信息安全政策
  • 风险评估方法论
  • 风险登记册与风险处置计划
  • 适用性声明(SoA)
  • 内部审核报告
  • 管理评审会议纪要
  • 纠正措施登记册
  • 指标与KPI仪表盘

Common Pitfalls

常见误区

  • Scope too broad or too narrow, leading to audit complications
  • Treating ISO 27001 as a checkbox exercise rather than embedding into business processes
  • Insufficient top management involvement and commitment
  • Failing to maintain documented evidence of control operation
  • Not performing regular risk reassessments as the threat landscape changes
  • Ignoring the 11 new controls in the 2022 edition during transition
  • 范围过宽或过窄,导致审核复杂化
  • 将ISO 27001视为走形式,而非融入业务流程
  • 最高管理层参与度与承诺不足
  • 未能保留控制措施运行的文档化证据
  • 未随威胁环境变化定期重新评估风险
  • 过渡期间忽略2022版新增的11项控制措施

Integration Points

集成要点

  • ISO 27002:2022: Detailed implementation guidance for Annex A controls
  • ISO 27005: Information security risk management methodology
  • ISO 27017: Cloud security controls
  • ISO 27018: Protection of PII in cloud services
  • ISO 27701: Privacy Information Management System (PIMS) extension
  • NIST CSF 2.0: Cross-mapping for dual compliance
  • SOC 2: Overlapping trust service criteria
  • ISO 27002:2022:附录A控制措施的详细实施指南
  • ISO 27005:信息安全风险管理方法论
  • ISO 27017:云安全控制措施
  • ISO 27018:云服务中个人可识别信息(PII)保护
  • ISO 27701:隐私信息管理体系(PIMS)扩展标准
  • NIST CSF 2.0:双合规交叉映射
  • SOC 2:重叠的信任服务准则

References

参考资料